Impact
In the addr_remap_address_map function of remap.c, a logic error permits a local attacker to gain System execution privileges without any user interaction. The flaw bypasses required privilege checks during address remapping, allowing the attacker to elevate authority to the highest system level on the device. This flaw is classified as CWE-693.
Affected Systems
Android operating systems on Google devices are affected. The advisory does not specify exact kernel versions, so any device running a vulnerable Android build should verify its kernel image and apply available security updates.
Risk and Exploitability
The EPSS score is < 1%, indicating a very low but non-zero exploitation probability. The CVSS score of 6.7 indicates moderate severity. The vulnerability is not listed in the CISA KEV catalog, and the flaw can provide a local attacker System execution privileges without user interaction. Exploitation does not require any special user action, so an attacker with physical or local remote access could potentially trigger the flaw. The lack of publicly known exploits implies the threat is likely low to medium.
OpenCVE Enrichment